Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Superset MEDIUM 6.5
CVE-2024-24779

Apache Superset with custom roles that include `can write on dataset` and without all data access permissions, allows for users to create virtual dat…

Fix: 3.1.1+
Fix from $1,600 2024-02-28
Superset MEDIUM 5.4
CVE-2024-26016

A low privilege authenticated user could import an existing dashboard or chart that they do not have access to and then modify its metadata, thereby …

Fix: 3.0.4 / 3.1.1+
Fix from $1,600 2024-02-28
GitLab MEDIUM 5.4
CVE-2023-3509

An issue has been discovered in GitLab affecting all versions before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting fro…

Fix: after 16.8.3
Fix from $1,600 2024-02-21
Microsoft Authentication HIGH 8.1
CVE-2023-46241

`discourse-microsoft-auth` is a plugin that enables authentication via Microsoft. On sites with the `discourse-microsoft-auth` plugin enabled, an att…

Fix: 2024-02-20+
Fix from $1,950 2024-02-21
macOS MEDIUM 5.5
CVE-2023-42860

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12.7.1, macOS Ventura 13.6.1…

Fix: 12.7.1 / 13.6.1+
Fix from $1,600 2024-02-21
Data Record Ad HIGH 7.8
CVE-2024-1155

Incorrect permissions in the installation directories for shared SystemLink Elixir based services may allow an authenticated user to potentially enab…

Fix: 2024_q1+
Fix from $1,950 2024-02-20
Data Record Ad HIGH 7.8
CVE-2024-1156

Incorrect directory permissions for the shared NI RabbitMQ service may allow a local authenticated user to read RabbitMQ configuration information an…

Fix: 2024_q1+
Fix from $1,950 2024-02-20
Digital Experience Platform MEDIUM 6.5
CVE-2024-25604

Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before service pack 3, 7.2 before fix pack 17, and …

Fix: 7.2 / 7.4.3.5+
Fix from $1,600 2024-02-20
Digital Experience Platform MEDIUM 5.4
CVE-2024-25149

Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsu…

Fix: 7.2 / 7.4.2+
Fix from $1,600 2024-02-20
Emui HIGH 7.5
CVE-2023-52374

Permission control vulnerability in the package management module.Successful exploitation of this vulnerability may affect service confidentiality.

No fix yet
Fix from $1,950 2024-02-18
Harmonyos HIGH 7.5
CVE-2023-52361

The VerifiedBoot module has a vulnerability that may cause authentication errors.Successful exploitation of this vulnerability may affect integrity.

No fix yet
Fix from $1,950 2024-02-18
Snapcenter MEDIUM 5.4
CVE-2024-21987

SnapCenter versions 4.8 prior to 5.0 are susceptible to a vulnerability which could allow an authenticated SnapCenter Server user to modify system …

Fix: 5.0+
Fix from $1,600 2024-02-16
Android MEDIUM 5.5
CVE-2024-0017

In shouldUseNoOpLocation of CameraActivity.java, there is a possible confused deputy due to a permissions bypass. This could lead to local informatio…

Patch available
Fix from $1,600 2024-02-16
Enterprise Server MEDIUM 6.5
CVE-2024-1482

An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to create new branches in public reposit…

Fix: 3.9.10 / 3.10.7+
Fix from $1,600 2024-02-14
F5os A MEDIUM 5.5
CVE-2024-24966

When LDAP remote authentication is configured on F5OS, a remote user without an assigned role will be incorrectly authorized.  Note: Software version…

Fix: 1.6.0+
Fix from $1,600 2024-02-14
Grafana MEDIUM 5.4
CVE-2023-6152

A user changing their email after signing up and verifying it can change it without verification in profile settings. The configuration option "veri…

Fix: after 2.5.0
Fix from $1,600 2024-02-13
Event Management And Registration HIGH 8.8
CVE-2024-24751

sf_event_mgt is an event management and registration extension for the TYPO3 CMS based on ExtBase and Fluid. In affected versions the existing access…

Patch available
Fix from $1,950 2024-02-13
Openrefine HIGH 7.5
CVE-2024-23833

OpenRefine is a free, open source power tool for working with messy data and improving it. A jdbc attack vulnerability exists in OpenRefine(version<=…

Fix: 3.7.8+
Fix from $1,950 2024-02-12
Pixelfed HIGH 8.8
CVE-2024-25108

Pixelfed is an open source photo sharing platform. When processing requests authorization was improperly and insufficiently checked, allowing attacke…

Fix: 0.11.11+
Fix from $1,950 2024-02-12
Web3 Crypto Wallet Login \& Nft Token Gating CRITICAL 9.8
CVE-2023-6036

The Web3 WordPress plugin before 3.0.0 is vulnerable to an authentication bypass due to incorrect authentication checking in the login flow in functi…

Fix: 3.0.0+
Fix from $2,300 2024-02-12
Gc370xa Firmware HIGH 8.1
CVE-2023-51761

In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could bypass authentication and acquire adm…

Mitigation only
Fix from $1,950 2024-02-09
Gc370xa Firmware CRITICAL 9.1
CVE-2023-43609

In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could obtain access to sensitive informatio…

Mitigation only
Fix from $2,300 2024-02-09
GitLab MEDIUM 6.5
CVE-2023-6564

An issue has been discovered in GitLab EE Premium and Ultimate affecting versions 16.4.3, 16.5.3, and 16.6.1. In projects using subgroups to define w…

Mitigation only
Fix from $1,600 2024-02-08
Graylog HIGH 8.8
CVE-2024-24824EPSS 34%

Graylog is a free and open log management platform. Starting in version 2.0.0 and prior to versions 5.1.11 and 5.2.4, arbitrary classes can be loaded…

Fix: 5.1.11 / 5.2.4+
Fix from $1,950 2024-02-07
Getwid MEDIUM 5.3
CVE-2023-6963

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 2.0.4. This makes it possible fo…

Fix: 2.0.5+
Fix from $1,600 2024-02-05
Phpmyfaq MEDIUM 6.5
CVE-2024-22208

phpMyFAQ is an Open Source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. The 'sharing FAQ' functionality allows any una…

Fix: 3.2.5+
Fix from $1,600 2024-02-05
Qts MEDIUM 6.5
CVE-2023-32967

An incorrect authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could al…

Mitigation only
Fix from $1,600 2024-02-02
Tivoli Application Dependency Discovery Manager HIGH 8.8
CVE-2023-47142

IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 could allow an attacker on the organization's local network to escalate …

Fix: after 7.3.0.10
Fix from $1,950 2024-02-02
Facilemanager HIGH 8.8
CVE-2024-24573

facileManager is a modular suite of web apps built with the sysadmin in mind. In versions 4.5.0 and earlier, when a user updates their profile, a POS…

Fix: 4.5.1+
Fix from $1,950 2024-01-31
Buildkit CRITICAL 9.8
CVE-2024-23653

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. In addition to running contain…

Fix: 0.12.5+
Fix from $2,300 2024-01-31